Joomla 插件 - cmsjunkie.com - J-BusinessDirectory 版本低于 6.2.3 存在未授权的所有权接管漏洞。攻击者可通过提交指定的公司和用户 ID,更改列表的所有权,包括那些已有所有者的列表。在 6.2.3 版本中,该操作已绑定到已认证的用户,并且仅允许对无主的列表进行操作。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| cmsjunkie.com | J-BusinessDirectory extension for Joomla | 1.0.0-6.2.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| cmsjunkie.com | J-BusinessDirectory extension for Joomla | 1.0.0-6.2.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-75949 | 10.0 CRITICAL | Joomla Extension - cmsjunkie.com - Arbitrary file upload / deletion (path traversal) in J |
| CVE-2026-75954 | 9.3 CRITICAL | Joomla Extension - cmsjunkie.com - SQL injection in trips search in J-BusinessDirectory < |
| CVE-2026-75956 | 8.7 HIGH | Joomla Extension - cmsjunkie.com - DOS vector in pagination parameter handling in J-Busine |
| CVE-2026-75951 | 6.9 MEDIUM | Joomla Extension - cmsjunkie.com - Insecure Direct Object Reference (multiple frontend/AP |
| CVE-2026-75955 | 5.1 MEDIUM | Joomla Extension - cmsjunkie.com - Reflected XSS / XML injection in J-BusinessDirectory < |
| CVE-2026-75952 | 4.6 MEDIUM | Joomla Extension - cmsjunkie.com - Cross-site request forgery in J-BusinessDirectory < 6. |
| CVE-2026-75953 | Joomla Extension - cmsjunkie.com - Open mail relay in J-BusinessDirectory < 6.2.3 |
No comments yet